SmartProvisioning
Check Point 1400 Appliances Centrally Managed Administration Guide R77.20.85 | 31
5.
In
Provisioning Profile
,
select the provisioning profile to assign to this gateway, from the list of
profiles created in SmartProvisioning.
6.
Click
Next
.
Cluster Names
The cluster members' names are shown with the configured prefix.
Click
Next
.
More Information
1.
Click
Edit
to override the settings of the template topology on each of the interfaces. For
example, select WAN and click Edit.
The interface window opens.
2.
In
IP Address Override
, enter the actual network IP address to override the template Network
address.
3.
Click
OK
and do the above steps again for all the interfaces.
4.
Click
Next
.
Communication Properties
1.
Select a member and click
Initialize
. Enter the trusted communication (SIC) details and click
OK
.
2.
Do this step again for the second member.
3.
Click
Next
.
VPN Properties
1.
Select how to create a VPN certificate:
•
For a CA certificate from the Internal Check Point CA, select
I wish to create a VPN
Certificate from the Internal CA
.
•
For a CA certificate from a third party (for example, if your organization already has
certificates from an external CA for other devices), clear this checkbox and request the
certificate from the appropriate CA server.
2.
Click
Next
.
Finish
1.
Click
Finish
. After the wizard finishes, wait until the SIC initialization completes. It can take a
few minutes. When it completes, you see the cluster object and its two members.
When you double-click the cluster object you can see that the topology is configured with the
actual addresses.
2.
On each Check Point Appliance, open the WebUI
Home
>
Security Management
page and click
Fetch Policy
to manually pull the policy immediately. Alternatively, the appliance connects to
the Security Management Server at predefined periodic intervals to pull the policy.
Содержание L-71
Страница 122: ......